@avalabs/evm-module
This package implements the core logic for the EVM (Ethereum Virtual Machine) module.
8
Versions
Limited Ecosystem License
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
martin.pradochriselbring-avalabsdes-ava
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| license | uncommon-license:Limited Ecosystem License | AI (license): Avalabs' standard custom license, not a security concern. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): CI-published with unchanged provenance; consistent with normal org maintainer rotation. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs typechain to generate contract bindings from local node_modules — no network access, deterministic codegen step. | ai | |
| phantom-deps | phantom-dep:@avalabs/types | AI (phantom-deps): Same-org monorepo package; phantom-dep heuristic is unreliable for transitive type-only imports. | ai | |
| phantom-deps | phantom-dep:@avalabs/core-etherscan-sdk | AI (phantom-deps): Same-org monorepo package; phantom-dep heuristic is unreliable for transitive imports. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): bn.js is referenced in config/type files; stable false positive for this package. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 3.9.4 | 16 / 14 | |
| 3.9.0 | 16 / 14 | |
| 3.8.0 | 15 / 14 | |
| 3.7.3 | 15 / 14 | |
| 3.0.2 | 15 / 14 | |
| 3.0.1 | 15 / 14 | |
| 2.1.0 | 15 / 14 | |
| 2.0.0 | 15 / 14 |
v3.9.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.